-
Amazon on Friday said it flagged and disrupted what it described as an opportunistic watering hole campaign orchestrated by the Russia-linked APT29 actors as part of their intelligence gathering efforts. The campaign used “compromised websites to redirect visitors to malicious infrastructure designed to trick users into authorizing attacker-controlled devices through Microsoft’s device code
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An abandoned update server associated with input method editor (IME) software Sogou Zhuyin was leveraged by threat actors as part of an espionage campaign to deliver several malware families, including C6DOOR and GTELAM, in attacks primarily targeting users across Eastern Asia. “Attackers employed sophisticated infection chains, such as hijacked software updates and fake cloud storage or login
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity teams worldwide have observed a surge in sophisticated campaigns exploiting both Windows and Linux vulnerabilities in recent months to achieve unauthorized system access.
These attacks often begin with phishing emails or malicious web content designed to deliver weaponized documents. Once opened, the embedded exploits target unpatched vulnerabilities in commonly used software components, allowing attackers to execute arbitrary code on victim machines.
As organizations struggle to keep pace with patch management, threat actors have intensified their focus on high-impact flaws that remain unaddressed in many environments.
Securelist researchers identified that several long-standing vulnerabilities in Microsoft Office’s Equation Editor continue to be a favorite initial access vector.
CVE-2018-0802 and CVE-2017-11882, both remote code execution flaws in the Equation Editor component, remain heavily exploited despite patches being available for years.
In addition, CVE-2017-0199, a flaw affecting Office and WordPad, provides another path for payload delivery.
These Office exploits are often combined with more recent Windows File Explorer and driver vulnerabilities—such as CVE-2025-24071, which enables NetNTLM credential theft via .library-ms files, and CVE-2024-35250, a ks.sys driver code execution issue—to establish a foothold and escalate privileges.
Beyond Microsoft Office, attackers have also leveraged WinRAR’s archive-handling weaknesses. CVE-2023-38831 and the directory traversal flaw CVE-2025-6218 allow adversaries to place malicious files outside the intended extraction path, hijacking system configurations or dropping persistence backdoors.
On the Linux side, the Dirty Pipe vulnerability (CVE-2022-0847) remains a critical favorite for privilege escalation, while CVE-2019-13272 and CVE-2021-22555 continue to be used to gain root access on unpatched servers.
Infection Mechanism
A particularly insidious infection mechanism combines Office-based delivery with secondary exploitation of system drivers. Securelist analysts noted that attackers craft RTF documents containing shellcode that invokes Equation Editor through OLE objects.
Once the vulnerability triggers, shellcode downloads a two-stage payload: a small loader and a full-featured malware binary.
The loader leverages CVE-2025-24071 to harvest NetNTLM hashes from incoming SMB connections, forwarding them to a C2 server.
The full payload then exploits CVE-2024-35250 to load a malicious driver into kernel space, granting attackers unrestricted code execution.
This dual-exploit chain allows adversaries to bypass user-level defenses and deploy rootkits undetected.
.webp)
Payload published online (Source – Securelist) In many incidents, once kernel-level control is achieved, attackers install custom C2 frameworks—such as Sliver or Havoc—to maintain persistence.
These implants include in-memory protection to evade antivirus scans and use legitimate Windows services to blend into normal processes.
By chaining publicly known exploits, actors can rapidly move from initial compromise to full system control without writing suspicious files to disk.
Vulnerability Details:-
CVE Description Exploit Type Affected Platform CVE-2018-0802 RCE in Office Equation Editor Embedded OLE exploit Windows CVE-2017-11882 RCE in Office Equation Editor Embedded OLE exploit Windows CVE-2017-0199 Control takeover via Office and WordPad Script-based document exploit Windows CVE-2023-38831 Improper file handling in WinRAR Archive code execution Windows CVE-2025-24071 NetNTLM credential theft via .library-ms files Credential dumping Windows CVE-2024-35250 Arbitrary code execution in ks.sys driver Kernel driver exploit Windows CVE-2022-0847 Dirty Pipe privilege escalation Pipe buffer overwrite Linux CVE-2019-13272 Improper privilege inheritance handling Privilege escalation Linux CVE-2021-22555 Heap overflow in Netfilter Heap-based overflow Linux CVE-2025-6218 Directory traversal in WinRAR Archive path manipulation Windows This consolidated view highlights the persistence of older vulnerabilities alongside newer flaws, underscoring the critical need for timely patching and comprehensive defense-in-depth strategies.
Organizations should prioritize updates for both user applications and system components to mitigate the risk of these prevalent exploits in real-world attacks.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.The post Threat Actors Leveraging Windows and Linux Vulnerabilities in Real-world Attacks to Gain System Access appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has confirmed that a security breach involving the Salesloft Drift platform is more extensive than initially reported, potentially compromising all authentication tokens connected to the service.
The new findings from the Google Threat Intelligence Group (GTIG) indicate that the incident, previously thought to be limited to Salesforce integrations, affects all third-party applications connected to Drift.
Google is now advising all Salesloft Drift customers to consider any and all authentication tokens stored in or linked to the Drift platform as potentially compromised and to take immediate remedial action.
The investigation into the breach began after GTIG identified a widespread data theft campaign conducted by a threat actor tracked as UNC6395.
OAuth Tokens Compromised
Between August 8 and August 18, 2025, the actor exploited compromised OAuth tokens associated with the Salesloft Drift third-party application to systematically export large volumes of data from numerous corporate Salesforce instances.
GTIG assesses that the primary motive was to harvest sensitive credentials, including Amazon Web Services (AWS) access keys, passwords, and Snowflake-related access tokens from the exfiltrated data.
In response to the initial discovery, Salesloft, in collaboration with Salesforce, took action on August 20, 2025. They revoked all active access and refresh tokens for the Drift application and temporarily removed it from the Salesforce AppExchange.
At the time, both companies believed the impact was contained to customers who integrated Drift with Salesforce.
However, the investigation took a critical turn on August 28, 2025, when it was confirmed that the threat actor had also compromised OAuth tokens for the “Drift Email” integration.
Evidence showed that on August 9, 2025, the actor used these tokens to access emails from a very small number of Google Workspace accounts that had been specifically configured to integrate with Salesloft. Google has clarified that the actor could not have accessed any other accounts within a customer’s Workspace domain.
“To be clear, there has been no compromise of Google Workspace or Alphabet itself,” a Google spokesperson stated.
In light of these new findings, Google has taken swift action to protect its customers. The company identified the impacted users, revoked the specific OAuth tokens granted to the Drift Email application, and disabled the integration functionality between Google Workspace and Salesloft Drift pending further investigation. All affected Google Workspace administrators are being notified directly.
The incident highlights the complex security challenges posed by interconnected third-party applications. While the breach did not stem from a vulnerability within the core platforms of Google or Salesforce, it demonstrates how a compromise in one service can create a ripple effect across integrated systems.
Salesloft has now engaged the cybersecurity firm Mandiant to assist in its ongoing investigation and has updated its security advisory.
Organizations using Salesloft Drift are strongly advised to take immediate defensive measures. Recommendations include conducting a thorough review of all third-party integrations connected to their Drift instance, revoking and rotating all associated credentials, and actively investigating all connected systems for any signs of unauthorized access or suspicious activity.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
The post Google Confirms Potential Compromise of All Salesloft Drift Customer Authentication Tokens appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
On August 28, 2025, the Hikvision Security Response Center (HSRC) issued Security Advisory SN No. HSRC-202508-01, detailing three critical vulnerabilities affecting various HikCentral products. Collectively assigned CVE identifiers CVE-2025-39245, CVE-2025-39246, and CVE-2025-39247, these vulnerabilities range in severity from moderate to high and could enable attackers to execute unauthorized commands, escalate privileges, or obtain administrative access. […]
The post Critical Hikvision Vulnerabilities Allow Remote Command Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Over the past year, security researchers have observed a growing trend of North Korean–linked developers establishing credible-looking profiles on popular code-sharing platforms such as GitHub, CodeSandbox, and Gist.
These accounts frequently host legitimate open-source projects alongside hidden payloads, allowing operators to mask malicious activity under the guise of normal developer contributions.
The overall goal appears to be multifaceted: generating revenue for state-sponsored programs, obtaining access to remote work contracts, and using those engagements as beachheads for more sophisticated cyber operations.
Initially, these profiles attracted attention due to unusually high activity levels and the adoption of advanced software stacks—including React.js front ends, Node.js back ends, and Dockerized deployment configurations—designed to impress prospective clients.
However, a deeper analysis revealed carefully obfuscated modules within certain repositories that leveraged compromised dependencies to deliver remote access trojans.
THE RAVEN FILE analysts noted that these repositories often employed minimalistic README files to distract from hidden directories named
.secretor.vendorwhere malicious payloads were staged.The impact of these operations has been significant. Several victims unknowingly installed tainted packages during routine dependency updates, granting attackers persistent access to corporate networks or cloud environments.
In one documented case, a financial services firm imported a library called
@jupyter-utils/rpcthat contained a loader script intercepting WebSocket connections and exfiltrating credentials via an embedded C2 channel.The combination of legitimate functionality and covert communication made detection extremely difficult for standard signature-based scanners.
Infection Mechanism and Persistence Tactics
A closer look at the infection mechanism reveals a multi-stage loader that activates only when certain environmental conditions are met.
Upon installation, the malicious package executes a preinstall script defined in
package.json:-"scripts": { "preinstall": "node scripts/setup.js" }The
setup.jsmodule then checks for the presence of common CI/CD directories (.gitlab-ci,.github/workflows) before deploying an encrypted payload into the application’s runtime directory.This payload, stored as
payload.enc, is decrypted in memory using a hard-coded key and immediately executed via Node’svmmodule:-const vm = require('vm'); const fs = require('fs'); const key = Buffer.from(process.env.DEPLOY_KEY, 'hex'); const cipher = fs.readFileSync('./payload.enc'); const decrypted = decrypt(cipher, key); vm.runInThisContext(decrypted);This below figure illustrates how the primary repository README masks the
scriptsfolder, while Figure 2 (“deepfake_result.png”) shows the deepfake profile image used to enhance credibility..webp)
DPRK IT Worker’s Git Profile (Source – THE RAVEN FILE) By embedding itself at the package manager level and leveraging CI/CD hooks, the malware achieves both stealthy installation and persistence.
Removal requires thorough dependency audits and validation of all installation scripts.
.webp)
Most wanted by the FBI (Source – THE RAVEN FILE) As organizations increasingly rely on open-source components, understanding these infection vectors is critical to safeguarding supply chains and maintaining trust in collaborative development platforms.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.The post DPRK IT Workers Using Code-Sharing Platforms to Secure New Remote Jobs appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Virustotal today unveiled a powerful addition to its Code Insight suite: a dedicated API endpoint that accepts code snippets—either disassembled or decompiled—and returns succinct summaries and detailed descriptions tailored for malware analysts. Launched over two years after the debut of Code Insight at RSA 2023, this endpoint represents a significant step toward automating reverse engineering […]
The post VirusTotal Launches Endpoint That Explains Code Functionality for Malware Analysts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hikvision has disclosed three significant security vulnerabilities affecting multiple versions of its HikCentral product suite that could enable attackers to execute malicious commands and gain unauthorized administrative access.
The vulnerabilities, assigned CVE identifiers CVE-2025-39245, CVE-2025-39246, and CVE-2025-39247, were reported to the Hikvision Security Response Center (HSRC) on by security researchers Yousef Alfuhaid, Nader Alharbi, Eduardo Bido, and Dr. Matthias Lutter.
Key Takeaways
1. CVE-2025-39247 lets unauthenticated attackers bypass access control in HikCentral Professional.
2. It exploits missing authentication checks on API endpoints.
3. Fix by upgrading and tightening network and logging controls.Access Control Vulnerability
The most severe vulnerability (CVE-2025-39247) affects HikCentral Professional versions V2.3.1 through V2.6.2, carrying a high CVSS v3.1 base score of 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
This access control flaw allows unauthenticated remote attackers to obtain administrator privileges without requiring user interaction or prior authentication credentials.
Technically, the root cause lies in insufficient access control within the web service API endpoints of HikCentral Professional.
Certain administrative functions fail to properly verify user authentication tokens, allowing specially crafted HTTP requests to invoke privileged operations.
CSV Injection Flaw
The first vulnerability (CVE-2025-39245) represents a CSV injection attack vector in HikCentral Master Lite versions V2.2.1 through V2.3.2.
With a CVSS score of 4.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L), this vulnerability enables attackers to inject executable commands through maliciously crafted CSV data files.
When unsuspecting users import these compromised CSV files, the embedded commands execute within the application context, potentially compromising system availability and data processing integrity.
Service Path Vulnerability
HikCentral FocSign versions V1.4.0 through V2.2.0 contain an unquoted service path vulnerability (CVE-2025-39246) scoring 5.3 on the CVSS scale (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
This Windows-specific vulnerability occurs when service executable paths contain spaces but lack proper quotation marks in the service configuration.
Authenticated attackers with local system access can exploit this flaw by placing malicious executables in strategic filesystem locations.
When the vulnerable service starts, Windows may execute the attacker’s payload instead of the legitimate service binary due to path resolution ambiguity.
CVE ID Title CVSS 3.1 Score Severity CVE-2025-39245 CSV Injection in HikCentral Master Lite 4.7 Medium CVE-2025-39246 Unquoted Service Path in HikCentral FocSign 5.3 Medium CVE-2025-39247 Access Control Bypass in HikCentral Professional 8.6 High Patching Required
Hikvision has released security patches addressing all three vulnerabilities. HikCentral Master Lite users should upgrade to version V2.4.0, while FocSign users require version V2.3.0.
The most critical update involves HikCentral Professional, where users must install either V2.6.3 or V3.0.1 to remediate the severe access control bypass vulnerability.
Organizations should prioritize patching CVE-2025-39247 due to its high severity rating and potential for remote exploitation without authentication.
The vulnerability’s network attack vector and changed scope classification indicate that successful exploitation could impact additional systems beyond the initially compromised target.
Security teams should implement comprehensive network segmentation to limit potential attack propagation.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
The post Multiple Hikvision Vulnerabilities Let Attackers Inject Executable Commands appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
VirusTotal today unveiled Virustotal’s New endpoint, which receives code requests and returns a description of its functionality for malware analysts, a powerful addition to its Code Insight platform.
Designed to streamline reverse engineering workflows, the new API endpoint pre-analyzes disassembled or decompiled code and highlights behaviors most relevant to malware hunters.
Early adopters report significant reductions in manual triage time, allowing analysts to focus on complex investigation steps rather than boilerplate documentation.
Key Takeaways
1. The analyze-binary endpoint returns AI-generated summaries and detailed descriptions of code snippets.
2. It learns from analyst-approved history to refine insights over time.
3. VT-IDA Plugin integration builds a persistent CodeInsight Notebook in IDA Pro.New Endpoint Overview
The new endpoint, api/v3/codeinsights/analyse-binary, accepts a JSON payload containing Base64-encoded code blocks alongside metadata for context. Payload parameters include:

Upon receiving a request, the endpoint returns two fields:
A concise overview of the function’s purpose, such as network I/O routines or anti-debugging logic. A detailed breakdown of control flow, API calls, string references, and potential obfuscation techniques.

New version of the plugin By chaining previous requests in the history array, the service builds a contextual model that learns as the analyst iterates.
For instance, if an initial query flags a custom XOR routine, subsequent analyses incorporate that knowledge to identify similar patterns more accurately, Virustotal said.
This chaining capability differentiates Code Insight from standalone static analysis, as the endpoint effectively “remembers” and refines its insights based on user-provided feedback.
Integration into IDA Pro
To demonstrate real-world utility, VirusTotal updated its VT-IDA Plugin to leverage the new endpoint directly within the IDA Pro interface.
Malware analysts can now select a function in the disassembly or decompiled view, invoke the plugin, and receive instant insights without leaving their reverse engineering environment. Key features include:
- Analysts can approve or modify the summary and description, capturing corrections or additional context.
- Approved analyses populate a notebook that persists across sessions, ensuring institutional knowledge is retained.
- Each plugin invocation sends the entire notebook history, enabling the endpoint to produce richer, more accurate analyses over time.
This endpoint marks a significant leap in integrating LLM-powered AI into traditional reverse engineering tools.
By automating the preliminary review of code blocks and learning iteratively from analyst feedback, Code Insight reduces repetitive tasks and accelerates threat discovery.
Although currently in trial mode, early feedback from the security community has been overwhelmingly positive.
As VirusTotal refines the service, analysts can expect broader format support, enhanced accuracy, and deeper contextual awareness, all aimed at empowering defenders in the ever-evolving malware landscape.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
The post Virustotal’s New Endpoint Provides Functionality Descriptions for Malware Analysts’ Code Requests appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have uncovered a sophisticated malvertising campaign on Meta’s Facebook platform in recent weeks that targets Android users with promises of a free TradingView Premium application.
These deceptive ads mimic official TradingView branding and visuals, luring unsuspecting victims to download what appears to be a legitimate APK.
Once installed, however, the app unleashes a highly advanced crypto-stealing trojan that leverages accessibility abuses and overlay techniques to harvest credentials, bypass two-factor authentication, and seize control of device functionality.
This campaign marks a significant evolution in mobile-focused malvertising, demonstrating how threat actors adapt traditional desktop-oriented strategies to increasingly lucrative Android ecosystems.
After initial discovery on July 22, 2025, the wave of malicious advertisements rapidly gained traction across Europe and beyond.
The ads redirect users to a cloned webpage at new-tw-view[.]online, where they download an APK from tradiwiw[.]online/tw-update.apk.
Upon installation, the dropper immediately requests powerful permissions, masquerading as legitimate update prompts that coax users into enabling Accessibility Services and granting device administration rights.
Bitdefender analysts noted that, in many cases, the dropper cleans up after itself by uninstalling its initial stub, leaving only the payload in place to avoid detection.
On August 22, Bitdefender researchers identified that at least 75 unique ads had been deployed since late July, reaching tens of thousands of users in the EU alone.
The attackers localized their lures in over a dozen languages—including Vietnamese, Portuguese, Spanish, Turkish, and Arabic—to maximize reach and credibility.
.webp)
Malicious ads (Source – Bitdefender) Targeting mobile users reflects a broader trend: as smartphones become central to financial operations—crypto wallets, mobile banking, and authentication apps—the stakes for successful compromise rise dramatically.
Technical Overview of Infection Mechanism
Delving into the infection chain reveals a multi-stage process designed for stealth and persistence. Upon execution, the dropper APK computes the MD5 checksum
788cb1965585f5d7b11a0ca35d3346ccand unpacks an embedded payload with checksum58d6ff96c4ca734cd7dfacc235e105bd.The payload is stored as an encrypted DEX resource within the application. A native library dynamically retrieves decryption keys and loads the hidden classes via reflection, bypassing standard signature checks.
// Reflection-based payload loading String dexPath = context.getFilesDir() + "/payload.dex"; FileOutputStream fos = new FileOutputStream(dexPath); fos.write(decryptedBytes); fos.close(); DexClassLoader loader = new DexClassLoader(dexPath, context.getCacheDir().getAbsolutePath(), null, context.getClassLoader()); Class<?> clazz = loader.loadClass("com.tradingview.updater.Updater"); Method init = clazz.getMethod("initialize", Context.class); init.invoke(null, context);.webp)
Accessibility permission prompt overlaying update screen (Source – Bitdefender) Once active, the malware registers as an accessibility service, granting it the ability to monitor keystrokes, intercept 2FA tokens from Google Authenticator, and display fake login screens over banking and crypto apps.
The code snippet above exemplifies how the malicious updater class is dynamically loaded, ensuring that static analysis tools may miss its presence.
Persistence is achieved by re-enabling accessibility services on reboot and hiding its icon from app drawers through
PackageManager.setComponentEnabledSetting, preventing user attempts to locate and remove the threat.This attack demonstrates a high degree of automation combined with manual-grade precision in targeting high-value assets on Android devices.
By weaponizing Facebook’s ad infrastructure and leveraging in-depth knowledge of the Android permission model, threat actors have created a potent campaign capable of global reach and significant financial impact.
Organizations and individuals alike must remain vigilant, scrutinizing app sources, verifying URLs, and limiting sideloading to trusted repositories.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.The post Threat Actors Weaponizing Facebook Ads with Free TradingView Premium App Lures That Delivers Android Malware appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


